Information Assurance and Security
Final Exam 2025 Questions and Answers
100% Pass
Host-based IDs (HIDS) - ANSWER-An intrusion detection system that examines
activity on an individual system
Network-based IDs (NIDS) - ANSWER-An intrusion detection system that
examines network activity that crosses it's path
Anomaly detection model - ANSWER-IDS model that builds a profile of normal
activity and detects variances
Misuse detection model - ANSWER-IDS model that relies on predefined
signatures to identify malicious activity and responds with programmed reactions
IDS Operation Categories - ANSWER-Behavior/Anomaly-based, Signature-based,
Heuristic
Content-based Signatures - ANSWER-Examine network packets or entries for
certain strings or flags
COPYRIGHT ©️ 2025 ALL RIGHTS RESERVED...TRUSTED & VERIFIED 1
, Context-based Signatures - ANSWER-Examine large patterns of activity to see
how they fit into surrounding activity
Major NIDS Components - ANSWER-Traffic controller, Analysis engine,
Reports, User interface
Intrusion Prevention System (IPS) - ANSWER-Monitors network traffic for
malicious behavior to block, reject, or redirect in real-time
Specifics of IPS - ANSWER-Has signature database, content based inspection,
protocol inspection, must sit in-line, but struggles with encryption
Honeypot - ANSWER-"Digital Sandbox" designed to contain and observe
attackers without risk
Honeynet - ANSWER-A collection of two or more honeypots
Protocol Analyzer (Packet Sniffer) - ANSWER-A software or hardware system
that can capture and decode traffic for IDS purposes
False Positive - ANSWER-When an alarm is created for benign traffic
False Negative - ANSWER-When hostile activity goes undetected and creates a
false sense of security
Baselining - ANSWER-Establishing a system's security state to create a safe and
secure "baseline"
COPYRIGHT ©️ 2025 ALL RIGHTS RESERVED...TRUSTED & VERIFIED 2
Final Exam 2025 Questions and Answers
100% Pass
Host-based IDs (HIDS) - ANSWER-An intrusion detection system that examines
activity on an individual system
Network-based IDs (NIDS) - ANSWER-An intrusion detection system that
examines network activity that crosses it's path
Anomaly detection model - ANSWER-IDS model that builds a profile of normal
activity and detects variances
Misuse detection model - ANSWER-IDS model that relies on predefined
signatures to identify malicious activity and responds with programmed reactions
IDS Operation Categories - ANSWER-Behavior/Anomaly-based, Signature-based,
Heuristic
Content-based Signatures - ANSWER-Examine network packets or entries for
certain strings or flags
COPYRIGHT ©️ 2025 ALL RIGHTS RESERVED...TRUSTED & VERIFIED 1
, Context-based Signatures - ANSWER-Examine large patterns of activity to see
how they fit into surrounding activity
Major NIDS Components - ANSWER-Traffic controller, Analysis engine,
Reports, User interface
Intrusion Prevention System (IPS) - ANSWER-Monitors network traffic for
malicious behavior to block, reject, or redirect in real-time
Specifics of IPS - ANSWER-Has signature database, content based inspection,
protocol inspection, must sit in-line, but struggles with encryption
Honeypot - ANSWER-"Digital Sandbox" designed to contain and observe
attackers without risk
Honeynet - ANSWER-A collection of two or more honeypots
Protocol Analyzer (Packet Sniffer) - ANSWER-A software or hardware system
that can capture and decode traffic for IDS purposes
False Positive - ANSWER-When an alarm is created for benign traffic
False Negative - ANSWER-When hostile activity goes undetected and creates a
false sense of security
Baselining - ANSWER-Establishing a system's security state to create a safe and
secure "baseline"
COPYRIGHT ©️ 2025 ALL RIGHTS RESERVED...TRUSTED & VERIFIED 2